The American Recovery Reinvestment Act and Health Care Reform Puzzle. Presentation Overview 2/27/2012

Size: px
Start display at page:

Download "The American Recovery Reinvestment Act and Health Care Reform Puzzle. Presentation Overview 2/27/2012"

Transcription

1 The American Recovery Reinvestment Act and Health Care Reform Puzzle Carolyn Heyman-Layne Alaska HCCA Regional Conference March 1, 2012 Presentation Overview ARRA and HITECH Breach Reporting: When, How and to Whom? Two Pieces of the Compliance Puzzle Both related to healthcare Both have deadlines in the past, 2014 and beyond Enforcement affects all Patient Protection and Affordable Care Act (PPACA) Current Legal Status of PPACA Compliance Issues in PPACA Employer Side of PPACA 2 1

2 ARRA and HITECH ARRA: American Recovery and Reinvestment Act 2/17/2009 $19.2 billion for health IT Numerous stimulus opportunities HITECH: Health Information Technology for Economic and Clinical Health Act Title XII of ARRA Deals with many of the health information provisions including changes to HIPAA Provides incentives for EHR for individual providers and certain organizations 3 HITECH: What you need to know Health Information Technology for Economic and Clinical Health (HITECH) Act: HIPAA Breach Notification Minimum Necessary Restriction Requests EHR Requirements Marketing & Communications Business Associates Additional Guidance Forthcoming EHRs: Meaningful Use 2

3 The Road to 2014: For Better or For Worse Good Increased Funding Clarification of Grey Areas Increased Enforcement for Business Associates Better Access to Records More Efficient Healthcare Delivery Not So Good No Excuses Increased Enforcement for Business Associates Increased Documentation Requirements Still waiting (may receive guidance during this conference) HITECH Changes to Security Rule Annual Technical Safeguards Guidance Review and follow Don t follow and be prepared to explain Breach Notification Requirements Notice to Patients Notice to HHS Differs from Alaska breach notification requirements Still in interim form until March 2012 (any day now) 3

4 HITECH vs. AK PIPA: Breach Reporting HITECH Only covers unsecured protected health information Written notification More than 500 affected requires notice to media Notice within 60 days of discovery Specific notice requirements Notice to HHS or annual log of breaches Alaska Personal Information Protection Act Covers personal information if reasonable likelihood of harm Written or electronic notice More than 300,000 requires notice to media Requires reporting to AG even if no harm caused Make sure this is covered in business associate agreements and vendor contracts What is a breach? HITECH/HIPAA Acquisition, access, use or disclosure of PHI in a manner not permitted under HIPAA, which compromises the security or privacy of the PHI. Only applies to unsecured PHI, such as unencrypted data on a laptop, etc. AK Personal Information Protection Act (AK PIPA) Unauthorized acquisition, or reasonable belief of unauthorized acquisition of personal information that compromises the security, confidentiality or integrity of the personal information. Only applies to personal information : not encrypted or redacted; combination of name and identifying number (SSN, DL#, credit card or bank account, etc.) 4

5 Exceptions to Breach HIPAA/HITECH Secured PHI Unintentional, good faith acquisition, access or use by person working under authority of covered entity, if within scope of authority and no further use or disclosure. Disclosures within same entity, or between entity and business associate or OHCA, under same terms. Good faith belief that no information could have been retained. AK PIPA Encrypted or Redacted PHI Good faith acquisition by an employee or agent for a legitimate purpose, as long as information not further disclosed. You Have a Breach Reporting Breaches Internally Form for employees to provide facts and necessary information for investigation and breach notification Policy regarding reporting and non-retaliation Procedures for who should be notified (IT, legal, compliance) 5

6 You Have a Breach What do you need to know? Who: Who accessed/disclosed the info? Did they have authorization? What: What info was accessed/disclosed? Was it encrypted? Name SSN, other identifying #s (Alaska PIPA) PHI Contact information When: When was it accessed/disclosed? Is the breach a onetime event or ongoing? How: How did the breach occur? Could it happen again? Can it be addressed or mitigated? Why: Was it intentional? Was there a violation of policy? You Have a Breach Internal Process: Notify mitigating departments immediately IT, legal, front desk, etc. if you can stop or contain the breach, do it ASAP Make sure and report up the chain Keep facts confidential until confirmed Determine if affiliates or business associates need to be involved in breach assessment Internal Analysis: Was the information part of our records? What is the likelihood of further use or disclosure? What is the foreseeable harm? To the individuals To the organization 6

7 Conducting the Analysis Risk Factors: Nature of data breached Potential harm to reputation Potential for harassment or prejudice Potential for identity theft Number of individuals affected Whether the breach was intentional Whether the information is easily redisclosed Whether the individual acting within the scope of their position Ability to mitigate the harm Addressing and Mitigating Addressing Breaches Internally Investigate Analyze Mitigate Notify Sanction Train Addressing Breaches Externally Mitigate Document Notify: Patients, State AG, OCR, Partners Make sure your staff is knowledgeable about the facts and the mitigating efforts 7

8 Reporting is Required How Do We Do It? HIPAA/HITECH Written notification by first class mail, unless individual has agreed to electronic communication. Website or major media if insufficient contact info for more than 10 people. Media notification required if more than 500 affected. AK PIPA Written notification, or electronic if primary method of communication is electronic, or if other contact info is insufficient. Website and major media if insufficient contact info for even one person. Media notification if more than 300,000 affected. Reporting Details HIPAA/HITECH Within 60 days of discovery of breach. Must include: Brief description of breach including date of breach and date of discovery. Description of PHI involved. Steps individual should take to protect themselves. Brief description of mitigation, investigation and protection measures taken by entity. Contact info for questions, including toll-free phone, , website or address. AK PIPA In the most expeditious time possible and without unreasonable delay. Content of notice not directly addressed. 8

9 Mitigating Efforts Important to look at root cause to determine possible mitigation steps Human error can t prevent, but can remind and retrain The easier the solution, the less of an excuse The harder/more expensive the solution, the more analysis that may be necessary Need to explain why you don t take all possible mitigating steps Need to describe the steps that you do take Document, document, document! Possible Mitigation Efforts Information available on-site for patients/clients. Informational sessions for patients/clients. Review and revise compliance plan. Sanctions against employees. Training for all employees. Work with partners/business associates. New technology. Follow-up credit checks for patients/clients. 9

10 Other Things to Consider HIPAA/HITECH Notice to HHS Annual log of breaches Who is responsible? Covered entity. Delay for investigation? Final rule still to come. Anyone else we should notify? Funders, partners, etc. AK PIPA Notice to consumer credit reporting agencies. Who is responsible for notice? Information distributor or collector. Red flags rule. HITECH Changes to Privacy Rule Minimum Necessary: Limited Data Set Safe Harbor Patient Requests for Restriction on PHI EHR Requirements Accounting of Disclosures Expanded Right to Records in Electronic Format PHI and Funding No Sales of PHI Opt-out for Fundraising 10

11 The Role of Business Associates Business Associates Directly Subject to HIPAA Responsible to Government Responsible through Business Associate Contracts May Need to Update Business Associate Agreements New Clarification/Category of Business Associates Reporting Breaches Another Qui Tam? Patients now have potential financial benefit from reporting HIPAA breaches Civil Monetary Penalties distributed directly to harmed individuals Amount of CMP tied to level of intent New Enforcement Rights State Attorney Generals Audits 11

12 HITECH: More than just HIPAA Medicare Incentive Payments: Meaningful use of a certified EHR Submission of clinical quality measures Penalties for failure to adopt EHRs Additional HITECH Funding: Education Grants Training Research Indian Health Services Grants PPACA: 900 Pages and counting 900 x 100 pages of regulations = 90,000 pages 24 12

13 Health Reform: Acts I, II, III Patient Protection and Affordable Care Act (P.L ) Original legislation, enacted March 23, 2010 Health Care and Education Reconciliation Act (P.L ) Changes by House, enacted March 30, 2010 TRICARE Affirmation Act Potential for: Additional Federal Laws Corresponding State Laws Over 100 Pages of regulations and guidance expected per page of legislation 25 Main Topics Covered by Legislation Titles I & II: Health Care and Insurance Coverage Title III: Delivery of Health Care Title IV: Prevention and Public Health Title V: Health Care Workforce Title VI: Fraud and Abuse Title VII: Health Technology Title VIII: CLASS Act (Assistance for Seniors and Disabled) Title IX: Taxes and Fees (How are we paying for this?) Title X: Amendments 26 13

14 Health Reform: Issuing Policies Exclusions for pre-existing conditions prohibited (2010, 2014) Dependent coverage extended to 26 (2010) Annual limits initially restricted, eventually prohibited Lifetime limits not allowed Rescission not permitted Policy and renewal guaranteed Premiums can only be adjusted for region, tobacco use, age and family composition No gender discrimination 27 Health Insurance Exchange Health Insurance Exchange for individuals and small businesses Less than 100 employees until 2017 Administered by government agency or non-profit Benefits: Competitive market Common rules on pricing and offering Supposed to provide more information for consumers Makes changing employment easier 28 14

15 Health Reform and Individual Coverage Requirements (2014) Required to have qualified health plan or pay the price Tax penalty starts small ($95) and increases ($695) Per person, per year Families capped at 2.5% of income or 3X penalty, whichever is larger Some exemptions apply: financial, religious, American Indian/Alaska Native Subsidies (2014) Income between 133% and 400% of FPL Cost Sharing for individuals/families between 100% and 400% of FPL 29 Health Reform and Health Care Delivery Evidence Based Practice Care Coordination and Service Integration Increased focus on innovation Quality Improvement Maternal, Infant and Early Childhood Home Visitation Programs Primary Care enhancement Increased pay Medical homes Coverage of preventive services Community Wellness grants Healthy lifestyles incentives Immunization program 30 15

16 Improvements in Quality and Delivery Accountable Care Organizations look out for fraud and abuse issues Comparative Effectiveness Research Malpractice Reform Pilots Dual eligible care coordination National quality improvement strategy National prevention and wellness strategy focus on preventive services Enhanced reporting and collection of data 31 ACA Compliance Provisions Requires Compliance Program as a Condition of Participation in Medicare All providers must certify that they have an effective compliance program Regulations expected for various provider types, nursing home regulations already issued Exact date for programs to be in place is not yet clear Enforcement activity increased Flexibility for varying size providers Better to start sooner, rather than later 32 16

17 ACA Required Compliance Plan Must contain core elements established by HHS Secretary in conjunction with OIG OIG Compliance Program Guidance may be helpful until further guidance issued: Failure to have an effective compliance program constitutes reckless disregard, which is the definition of knowingly submitting a false claim. United States v. Merck-Medco Managed Care LLC, 336 F.Supp.2d 430, (E.D. Pa. 2004). 33 ACA Repayment and Disclosures Congress clarified obligation to report and refund Medicare and Medicaid overpayments: Now very clear that overpayments are to be reported and returned to Secretary, State, an intermediary, carrier or contractor as appropriate Must notify Secretary, State, intermediary, carrier or contractor in writing of reason for overpayment Must be done by later of: 60 days after identification Date any corresponding cost report is due Problem: When is it identified? What about investigation? Liability for anyone who knows of an overpayment and fails to report/return it 34 17

18 ACA Definitions Clarified Overpayment: Any funds that a person receives or retains under title XVIII or XIX to which the person, after applicable reconciliation, is not entitled under such title Person: Provider of services, supplier, Medicaid managed care organization, Medicare Advantage organization or Medicare Part D Prescription Drug Plan sponsor Qui tam original source relaxed: person has knowledge that is independent of and materially adds to the publicly disclosed allegations or transactions. 35 ACA Fraud and Abuse Enforcement Additional $350 million over next 10 years to fight fraud in the healthcare system Tougher sentencing for criminal activity Enhanced screening requirements Enhanced enrollment requirements Increased sharing of data across government 36 18

19 ACA Fraud and Abuse Enforcement Expanded overpayment recovery efforts HHS authorized to suspend Medicare/Medicaid payments pending an investigation of credible allegation of fraud (not defined) Greater oversight of private insurance Improper Payments Elimination and Recovery Act specifically authorized auditors paid on contingency 37 Constitutional Challenge Predictions What is going on now? Circuit court decisions vary To be heard by Supreme Court in March Decision predicted in June

20 Constitutional Challenge Predictions What is next? Severability issues will arise if individual mandate unconstitutional, how much of PPACA must be repealed? What about programs that have already started? Will this tear the whole Act apart? 39 Health Reform Resources The law: Federal Guidance Kaiser Family Foundation - State Guidance

21 Challenges for Employers Reporting Requirements: 1099 Requirement Businesses required to file 1099 with IRS for every vendor conducting a transaction in excess of $600. REPEALED!!!!!!!! W-2 Required to report aggregate cost of coverage Determining What Rules Apply Determining What Coverage Employees Are Choosing 41 The Rules for Employers If an employer chooses to provide health insurance to all employees, the health insurance must meet both of the requirements listed below to completely avoid a penalty. Insurance must pay for at least 60% of covered health care expenses for a typical population. Employee should not have to pay more than 9.5% of family income for the employer plan. Or it may choose to provide a non-compliant health insurance plan, which would result in a reduced penalty amount, but would not eliminate the penalties altogether

22 Determining How the Rules Apply # Description Penalties Cost 1. Provide PPACA compliant health coverage for all employees. 2. Provide limited health plan to employees. None Penalty A = $3,000/yr. x (# of full-time equivalent employees receiving the tax credit - 30) Cost of health insurance plan that pays for at least 60% of covered health care expenses, with employee cost limited to 9.5% of family income or less. Cost of limited health insurance plan for those employees who choose the plan + Penalty A. Penalty A Example 1: If Employer has 100 full-time equivalents and 80 select the employer plan and 20 select the tax credit for alternate coverage, then there would be no penalty because the number of employees receiving tax credit does not exceed 30. Penalty A Example 2: If Employer has 100 full-time equivalents and 50 select the employer plan and 50 select the tax credit for alternate coverage, then the penalty would equal $3,000 x (50-30) = $60,000. Penalty A Example 3: If Employer has 100 full-time equivalents and 10 select the employer plan and 90 select the tax credit for alternate coverage, then the penalty would exceed the total for Penalty B below ($3,000 x = $180,000) and so Penalty A would equal Penalty B: $140,000. Employer would pay this penalty in addition to the cost for the ten employees who selected the plan. 3. Continue to provide no insurance for employees. Penalty B = $2,000/yr. x (# of full-time equivalent employees 30) Penalty B Penalty B Example: If Employer has 100 full-time equivalents, it would pay $2,000 x (100-30) = $140, Guessing game Cost of fully PPACA compliant health plan < Penalty B = Implement compliant plan. Cost of fully PPACA compliant health plan > Penalty B = Conduct additional analysis of limited health plan costs. Estimated cost of limited plan + Penalty A < Penalty B = Offer limited plan. Estimated cost of limited plan + Penalty A > Penalty B = Offer nothing.???????????????? 44 22

23 Other Employer Challenges Challenges: Businesses with less than 50 employees not required to provide insurance, but employees will still require coverage Confusion over requirements and how to apply them Employers that offer coverage will have to provide a free choice voucher to employees with incomes less than 400% FPL whose share of the premium exceeds 8%, but is less than 9.5% of their income???? Rules vary for size of employer, number of employees receiving tax credits, number of employees in exchange Growth many credits phase out as your business size increases, or your salaries increase Lost productivity with employees figuring out insurance options 45 Questions? heyman-layne@alaskalaw.pro (907) Sedor, Wendlandt, Evans & Filippi, LLC 46 23

The American Recovery Reinvestment Act. and Health Care Reform Puzzle

The American Recovery Reinvestment Act. and Health Care Reform Puzzle The American Recovery Reinvestment Act and Health Care Reform Puzzle Carolyn Heyman-Layne Alaska HCCA Conference March 1, 2012 Comparison of Breach Notification Provisions in the HITECH Act 1 and the Alaska

More information

Interim Date: July 21, 2015 Revised: July 1, 2015

Interim Date: July 21, 2015 Revised: July 1, 2015 HIPAA/HITECH Page 1 of 7 Effective Date: September 23, 2009 Interim Date: July 21, 2015 Revised: July 1, 2015 Approved by: James E. K. Hildreth, Ph.D., M.D. President and Chief Executive Officer Subject:

More information

HIPAA Training. HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel

HIPAA Training. HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel HIPAA Training HOPE Health Facility Administrators June 2013 Isaac Willett and Jason Schnabel Agenda HIPAA basics HITECH highlights Questions and discussion HIPAA Basics Legal Basics Health Insurance Portability

More information

Management Alert Final HIPAA Regulations Issued

Management Alert Final HIPAA Regulations Issued Management Alert Final HIPAA Regulations Issued After much anticipation, the Department of Health and Human Services (HHS) has issued its omnibus set of final regulations modifying and clarifying the privacy,

More information

HIPAA COMPLIANCE ROADMAP AND CHECKLIST FOR BUSINESS ASSOCIATES

HIPAA COMPLIANCE ROADMAP AND CHECKLIST FOR BUSINESS ASSOCIATES HIPAA COMPLIANCE ROADMAP AND CHECKLIST FOR BUSINESS ASSOCIATES The Health Information Technology for Economic and Clinical Health Act (HITECH Act), enacted as part of the American Recovery and Reinvestment

More information

Safeguarding Your HIPAA and Personal Health Information Data. Robert Hess, Office of General Counsel Steve Cosentino, Stinson Morrison Hecker

Safeguarding Your HIPAA and Personal Health Information Data. Robert Hess, Office of General Counsel Steve Cosentino, Stinson Morrison Hecker Safeguarding Your HIPAA and Personal Health Information Data Robert Hess, Office of General Counsel Steve Cosentino, Stinson Morrison Hecker 1 Overview» Patient information confidentiality Grant requirements

More information

HIPAA: Final Omnibus Rule is Here Arizona Society for Healthcare Risk Managers November 15, 2013

HIPAA: Final Omnibus Rule is Here Arizona Society for Healthcare Risk Managers November 15, 2013 HIPAA: Final Omnibus Rule is Here Arizona Society for Healthcare Risk Managers November 15, 2013 Pat Henrikson, Banner Health HIPAA Compliance Program Director, Chief Privacy Officer Agenda Background

More information

HITECH and HIPAA: Highlights for Health Departments. Aimee Wall UNC School of Government

HITECH and HIPAA: Highlights for Health Departments. Aimee Wall UNC School of Government HITECH and HIPAA: Highlights for Health Departments Aimee Wall UNC School of Government When Congress enacted sweeping legislation in February designed to stimulate the nation s economy, it incorporated

More information

AFTER THE OMNIBUS RULE

AFTER THE OMNIBUS RULE AFTER THE OMNIBUS RULE 1 Agenda Omnibus Rule Business Associates (BAs) Agreement Breach Notification Change Breach Reporting Requirements (Federal and State) Notification to Care1st Health Plan Member

More information

IACT Medical Trust. June 28, Jim Hamilton (317) HIPAA Privacy Training Bose McKinney & Evans LLP

IACT Medical Trust. June 28, Jim Hamilton (317) HIPAA Privacy Training Bose McKinney & Evans LLP IACT Medical Trust HIPAA Privacy Training June 28, 2012 Jim Hamilton (317) 684-5419 jhamilton@boselaw.com 2009 Bose McKinney & Evans LLP HIPAA Overview 2009 Bose McKinney & Evans LLP The Privacy Rule HIPAA

More information

HIPAA OMNIBUS RULE. The rule makes it easier for parents and others to give permission to share proof of a child s immunization with a school

HIPAA OMNIBUS RULE. The rule makes it easier for parents and others to give permission to share proof of a child s immunization with a school ASPPR The omnibus rule greatly enhances a patient s privacy protections, provides individuals new rights to their health information, and strengthens the government s ability to enforce the law. The changes

More information

Compliance Steps for the Final HIPAA Rule

Compliance Steps for the Final HIPAA Rule Brought to you by The Alpha Group for the Final HIPAA Rule On Jan. 25, 2013, the Department of Health and Human Services (HHS) issued a final rule under HIPAA s administrative simplification provisions.

More information

BREACH NOTIFICATION POLICY

BREACH NOTIFICATION POLICY PRIVACY 2.0 BREACH NOTIFICATION POLICY Scope: All subsidiaries of Universal Health Services, Inc., including facilities and UHS of Delaware Inc. (collectively, UHS ), including UHS covered entities ( Facilities

More information

Fifth National HIPAA Summit West

Fifth National HIPAA Summit West Fifth National HIPAA Summit West Privacy and Security under the HITECH Act W. Reece Hirsch Paul T. Smith, Partner, Partner, Hooper, Lundy & Bookman 1 Developments The Health Information Technology for

More information

HIPAA PRIVACY REQUIREMENTS. Dana L. Thrasher Robert S. Ellerbrock, III Constangy, Brooks & Smith, LLP

HIPAA PRIVACY REQUIREMENTS. Dana L. Thrasher Robert S. Ellerbrock, III Constangy, Brooks & Smith, LLP HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Robert S. Ellerbrock, III Constangy, Brooks & Smith, LLP dthrasher@constangy.com (205) 226-5464 1 Reasons for HIPAA Privacy Rules Perceived need for protection

More information

Legal and Privacy Implications of the HIPAA Final Omnibus Rule

Legal and Privacy Implications of the HIPAA Final Omnibus Rule Legal and Privacy Implications of the HIPAA Final Omnibus Rule February 19, 2013 Pillsbury Winthrop Shaw Pittman LLP Faculty Gerry Hinkley Partner Pillsbury Winthrop Shaw Pittman LLP Deven McGraw Director,

More information

ALERT. November 20, 2009

ALERT. November 20, 2009 ALERT HIPAA PRIVACY FOR EMPLOYERS HAS CHANGED. IMMEDIATE ACTION IS REQUIRED. November 20, 2009 The American Recovery and Reinvestment Act of 2009 ( ARRA ) also known as the Economic Stimulus Bill made

More information

HIPAA OMNIBUS FINAL RULE

HIPAA OMNIBUS FINAL RULE HIPAA OMNIBUS FINAL RULE Webinar Series Part 3 Breach Notification April 16, 2013 I. BACKGROUND 2 1 Background > HIPAA Omnibus Final Rule: Announced on January 17, 2013 Published in Federal Register on

More information

Disclaimer LEGAL ISSUES IN PHYSICAL THERAPY

Disclaimer LEGAL ISSUES IN PHYSICAL THERAPY LEGAL ISSUES IN PHYSICAL THERAPY Paul J. Welk, PT, JD Tucker Arensberg, P.C. pwelk@tuckerlaw.com 2017 PHCA Annual Convention 1 Disclaimer The purpose of this presentation is to provide a general overview

More information

The Impact of Final Omnibus HIPAA/HITECH Rules. Presented by Eileen Coyne Clark Niki McCoy September 19, 2013

The Impact of Final Omnibus HIPAA/HITECH Rules. Presented by Eileen Coyne Clark Niki McCoy September 19, 2013 The Impact of Final Omnibus HIPAA/HITECH Rules Presented by Eileen Coyne Clark Niki McCoy September 19, 2013 0 Disclaimer The material in this presentation is not meant to be construed as legal advice

More information

Changes to HIPAA Privacy and Security Rules

Changes to HIPAA Privacy and Security Rules Changes to HIPAA Privacy and Security Rules STEPHEN P. POSTALAKIS BLAUGRUND, HERBERT AND MARTIN 300 WEST WILSON BRIDGE ROAD, SUITE 100 WORTHINGTON, OHIO 43085 SPP@BHMLAW.COM PERSONNEL COUNCIL FRANKLIN

More information

2011 Miller Johnson. All rights reserved. 1. HIPAA Compliance: Privacy and Security Changes under HITECH HITECH. What is HITECH? Mary V.

2011 Miller Johnson. All rights reserved. 1. HIPAA Compliance: Privacy and Security Changes under HITECH HITECH. What is HITECH? Mary V. HIPAA Compliance: Privacy and Security Changes under HITECH Mary V. Bauman www.millerjohnson.com The materials and information have been prepared for informational purposes only. This is not legal advice,

More information

ARRA s Amendments to HIPAA Privacy & Security Rules

ARRA s Amendments to HIPAA Privacy & Security Rules ARRA s Amendments to HIPAA Privacy & Security Rules Georgina L. O Hara Jessica R. Bernanke April 29, 2009 www.morganlewis.com Amended HIPAA Privacy and Security Rules HIPAA Amendments are in The Health

More information

Long-Awaited HITECH Final Rule: Addressing the Impact on Operations of Covered Entities and Business Associates

Long-Awaited HITECH Final Rule: Addressing the Impact on Operations of Covered Entities and Business Associates Long-Awaited HITECH Final Rule: Addressing the Impact on Operations of Covered Entities and Business Associates March 7, 2013 Brad M. Rostolsky Partner Reed Smith LLP brostolsky@reedsmith.com Nancy E.

More information

OVERVIEW OF RECENT CHANGES IN HIPAA AND OHIO PRIVACY LAWS

OVERVIEW OF RECENT CHANGES IN HIPAA AND OHIO PRIVACY LAWS Franklin J. Hickman Janet L. Lowder David A. Myers Elena A. Lidrbauch Judith C. Saltzman Mary B. McKee Amanda M. Buzo Lisa Montoni Garvin Andrea Aycinena Penton Building 1300 East Ninth Street Suite 1020

More information

Long-Awaited HITECH Final Rule: Addressing the Impact on Operations of Covered Entities and Business Associates

Long-Awaited HITECH Final Rule: Addressing the Impact on Operations of Covered Entities and Business Associates Long-Awaited HITECH Final Rule: Addressing the Impact on Operations of Covered Entities and Business Associates November 7, 2013 Brad M. Rostolsky Partner Reed Smith LLP brostolsky@reedsmith.com Nancy

More information

New HIPAA Breach Rules NAHU presents the WHAT and WHYs. Agenda

New HIPAA Breach Rules NAHU presents the WHAT and WHYs. Agenda New HIPAA Breach Rules NAHU presents the WHAT and WHYs Presenters: David Smith JD, Vice President, Ebenconcepts Tom Jacobs JD, co-ceo eflexgroup Moderator: Ric Joyner CEBS CFCI, co-ceo, eflexgroup 1 Agenda

More information

Breach Policy. Applicable Standards from the HITRUST Common Security Framework. Applicable Standards from the HIPAA Security Rule

Breach Policy. Applicable Standards from the HITRUST Common Security Framework. Applicable Standards from the HIPAA Security Rule Breach Policy To provide guidance for breach notification when impressive or unauthorized access, acquisition, use and/or disclosure of the ephi occurs. Breach notification will be carried out in compliance

More information

Highlights of the Omnibus HIPAA/HITECH Final Rule

Highlights of the Omnibus HIPAA/HITECH Final Rule Highlights of the Omnibus HIPAA/HITECH Final Rule Health Law Whitepaper Katherine M. Layman 215.665.2746 klayman@cozen.com Gregory M. Fliszar 215.665.7276 gfliszar@cozen.com Judy Wang Mayer 215.665.4737

More information

COMPLIANCE TRAINING 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T

COMPLIANCE TRAINING 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T COMPLIANCE TRAINING 2015 QUALITY MANAGEMENT COMPLIANCE DEPARTMENT 2015 C O M P L I A N C E P R O G R A M - F W A - H I P A A - C O D E O F C O N D U C T Compliance Program why? Ensure ongoing education

More information

NPRM: Modifications to the HIPAA Privacy, Security, and Enforcement Rules under HITECH

NPRM: Modifications to the HIPAA Privacy, Security, and Enforcement Rules under HITECH NPRM: Modifications to the HIPAA Privacy, Security, and Enforcement Rules under HITECH Speakers Lisa A. Gallagher, BSEE, CISM, CPHIMS Senior Director, Privacy and Security HIMSS lgallagher@himss.org Amy

More information

OMNIBUS RULE ARRIVES

OMNIBUS RULE ARRIVES AFTER THE OMNIBUS RULE 1 Agenda Omnibus Rule is here Business Associates (BAs) Agreement Breach Notification Change Breach Reporting Requirements (Federal and State) Notification to Care1st Health Plan

More information

HIPAA Basic Training for Health & Welfare Plan Administrators

HIPAA Basic Training for Health & Welfare Plan Administrators 2010 Human Resources Seminar HIPAA Basic Training for Health & Welfare Plan Administrators Norbert F. Kugele What We re going to Cover Important basic concepts Who needs to worry about HIPAA? Complying

More information

Preparing for a HIPAA Audit & Hot Topics in Health Care Reform

Preparing for a HIPAA Audit & Hot Topics in Health Care Reform Preparing for a HIPAA Audit & Hot Topics in Health Care Reform 2013 San Francisco Mid-Sized Retirement & Healthcare Plan Management Conference March 17-20, 2013 Elizabeth Loh, Esq. Copyright Trucker Huss,

More information

Anti-Kickback Statute and False Claims Act Enforcement

Anti-Kickback Statute and False Claims Act Enforcement Anti-Kickback Statute and False Claims Act Enforcement Nicholas Gachassin, III, Esq. Gachassin Law Firm, LLC Nick3@gachassin.com Press Conference on Health Care Fraud and the Affordable Care Act May 13,

More information

HHS, Office for Civil Rights. IAPP October 11, 2012

HHS, Office for Civil Rights. IAPP October 11, 2012 HHS, Office for Civil Rights IAPP October 11, 2012 Enforce federal civil rights laws and the HIPAA Privacy and Security Rules HQ and 10 Regional Offices Region IX has jurisdiction over covered entities

More information

New. To comply with HIPAA notice requirements, all Providence covered entities shall follow, at a minimum, the specifications described below.

New. To comply with HIPAA notice requirements, all Providence covered entities shall follow, at a minimum, the specifications described below. Subject: Protected Health Information Breach Notification Policy Department: Enterprise Risk Management Services Executive Sponsor: SVP/Chief Risk Officer Approved by: Rod Hochman, MD President/CEO Policy

More information

H E A L T H C A R E L A W U P D A T E

H E A L T H C A R E L A W U P D A T E L O U I S V I L L E. K Y S E P T E M B E R 2 0 0 9 H E A L T H C A R E L A W U P D A T E L E X I N G T O N. K Y B O W L I N G G R E E N. K Y N E W A L B A N Y. I N N A S H V I L L E. T N M E M P H I S.

More information

New Federal Legislation Affecting Health Plans

New Federal Legislation Affecting Health Plans New Federal Legislation Affecting Health Plans New COBRA Subsidy New Special Enrollment Rights New Privacy and Security Requirements in the HITECH Act Leslie Anderson Jessica Forbes Olson Mark Kinney March

More information

The American Recovery and Reinvestment Act of 2009: Health Information Privacy and Security Provisions Here We Go Again

The American Recovery and Reinvestment Act of 2009: Health Information Privacy and Security Provisions Here We Go Again ClientAdvisory The American Recovery and Reinvestment Act of 2009: Health Information Privacy and Security Provisions Here We Go Again February 26, 2009 On February 17, 2009, President Obama signed into

More information

The wait is over HHS releases final omnibus HIPAA privacy and security regulations

The wait is over HHS releases final omnibus HIPAA privacy and security regulations The wait is over HHS releases final omnibus HIPAA privacy and security regulations The Department of Health and Human Services (HHS) published long-anticipated (and longoverdue) omnibus regulations under

More information

HIPAA PRIVACY AND SECURITY RULES APPLY TO YOU! ARE YOU COMPLYING? RHODE ISLAND INTERLOCAL TRUST LINN F. FREEDMAN, ESQ. JANUARY 29, 2015.

HIPAA PRIVACY AND SECURITY RULES APPLY TO YOU! ARE YOU COMPLYING? RHODE ISLAND INTERLOCAL TRUST LINN F. FREEDMAN, ESQ. JANUARY 29, 2015. HIPAA PRIVACY AND SECURITY RULES APPLY TO YOU! ARE YOU COMPLYING? RHODE ISLAND INTERLOCAL TRUST LINN F. FREEDMAN, ESQ. JANUARY 29, 2015. PURPOSE OF PRESENTATION To Discuss Laws Governing Use and Disclosure

More information

Summary of the Impact of Health Care Reform on Employers

Summary of the Impact of Health Care Reform on Employers Summary of the Impact of Health Care Reform on Employers How to Use this Summary This summary identifies the main provisions of the Patient Protection and Affordable Care Act (Act), as amended by the Health

More information

Hayden W. Shurgar HIPAA: Privacy, Security, Enforcement, HITECH, and HIPAA Omnibus Final Rule

Hayden W. Shurgar HIPAA: Privacy, Security, Enforcement, HITECH, and HIPAA Omnibus Final Rule Hayden W. Shurgar HIPAA: Privacy, Security, Enforcement, HITECH, and HIPAA Omnibus Final Rule 1 IMPORTANCE OF STAFF TRAINING HIPAA staff training is a key, required element in a covered entity's HIPAA

More information

Saturday, April 28 Medical Ethics: HIPAA Privacy and Security Rules

Saturday, April 28 Medical Ethics: HIPAA Privacy and Security Rules Saturday, April 28 Medical Ethics: HIPAA Privacy and Security Rules Gina Campanella, JD HIPAA & The Medical Practice Requirements for Privacy, Security and Breach Notification Gina L. Campanella, Esq.

More information

LEGAL ISSUES IN HEALTH IT SECURITY

LEGAL ISSUES IN HEALTH IT SECURITY LEGAL ISSUES IN HEALTH IT SECURITY Webinar Hosted by Uluro, a Product of Transformations, Inc. March 28, 2013 Presented by: Kathie McDonald-McClure, Esq. Wyatt, Tarrant & Combs, LLP 500 West Jefferson

More information

8/14/2013. HIPAA Privacy & Security 2013 Omnibus Final Rule update. Highlights from Final Rules January 25, 2013

8/14/2013. HIPAA Privacy & Security 2013 Omnibus Final Rule update. Highlights from Final Rules January 25, 2013 HIPAA Privacy & Security 2013 Omnibus Final Rule update Dan Taylor, Infinisource Copyright 2013 All rights reserved. Highlights from Final Rules January 25, 2013 Made business associates directly liable

More information

Compliance Steps for the Final HIPAA Rule

Compliance Steps for the Final HIPAA Rule Compliance Steps for the Final HIPAA Rule On Jan. 25, 2013, the Department of Health and Human Services (HHS) issued a final rule under HIPAA s administrative simplification provisions. The final rule

More information

HIPAA Overview Health Insurance Portability and Accountability Act. Premier Senior Marketing, Inc

HIPAA Overview Health Insurance Portability and Accountability Act. Premier Senior Marketing, Inc HIPAA Overview Health Insurance Portability and Accountability Act Premier Senior Marketing, Inc HIPAA Defined Acronym that stands for the Health Insurance Portability and Accountability Act, a US law

More information

HIPAA Enforcement Under the HITECH Act; The Gloves Come Off

HIPAA Enforcement Under the HITECH Act; The Gloves Come Off HIPAA Enforcement Under the HITECH Act; The Gloves Come Off Leeann Habte, Esq. Michael Scarano, Esq. December 6, 2011 Attorney Advertising Prior results do not guarantee a similar outcome Models used are

More information

Legislative Update HIPAA/HITECH

Legislative Update HIPAA/HITECH Legislative Update HIPAA/HITECH Richard C. Stevens, Attorney Martin, Pringle, Oliver, Wallace & Bauer, LLP http://martinpringle.com Topics Legislative Update HIPAA/HITECH q Enforcement Activities q Meaningful

More information

Presented by Marti Arvin Chief Compliance Officer UCLA Health Sciences

Presented by Marti Arvin Chief Compliance Officer UCLA Health Sciences Presented by Marti Arvin Chief Compliance Officer UCLA Health Sciences 1 Brief discussion of where we have been and where we are going Discussion of Federal Enforcement Actions Privacy and Security issue

More information

Getting a Grip on HIPAA

Getting a Grip on HIPAA Getting a Grip on HIPAA Privacy and Security of Health Information in the Post-HITECH Age Jean C. Hemphill hemphill@ballardspahr.com 215.864.8539 Edward I. Leeds leeds@ballardspahr.com 215.864.8419 Amy

More information

HIPAA & The Medical Practice

HIPAA & The Medical Practice HIPAA & The Medical Practice Requirements for Privacy, Security and Breach Notification Gina L. Campanella, JD, MHA, CHA Founder & Principal, Campanella Law Office Of Counsel, The Beinhaker Law Firm BEINHAKER,

More information

Coping with, and Taking Advantage of, HIPAA s New Rules!! Deven McGraw Director, Health Privacy Project April 19, 2013!

Coping with, and Taking Advantage of, HIPAA s New Rules!! Deven McGraw Director, Health Privacy Project April 19, 2013! Coping with, and Taking Advantage of, HIPAA s New Rules!!! Deven McGraw Director, Health Privacy Project April 19, 2013! Status of Federal Privacy Regulations! Omnibus Rule (Data Breach, Enforcement, HITECH,

More information

CLIENT UPDATE. HIPAA s Final Rule: The Impact on Covered Entities, Business Associates and Subcontractors

CLIENT UPDATE. HIPAA s Final Rule: The Impact on Covered Entities, Business Associates and Subcontractors CLIENT UPDATE February 20, 2013 HIPAA s Final Rule: The Impact on Covered Entities, Business Associates and Subcontractors On January 25, 2013, the U.S. Department of Health and Human Services ( DHHS )

More information

Medical Monitoring Program: PPACA and CMS Final Recommended Guidelines vs. Rules: New License Monthly Screening Requirements

Medical Monitoring Program: PPACA and CMS Final Recommended Guidelines vs. Rules: New License Monthly Screening Requirements PPACA and CMS Final Recommended Guidelines vs. Rules: New License Monthly Screening Requirements The Patient Protection and Affordable Care Act of 2010, as amended by the Health Care and Education Reconciliation

More information

HIPAA THE NEW RULES. Highlights of the major changes under the Omnibus Rule

HIPAA THE NEW RULES. Highlights of the major changes under the Omnibus Rule HIPAA THE NEW RULES Highlights of the major changes under the Omnibus Rule AUTHOR Gamelah Palagonia, Founder CIPM, CIPP/IT, CIPP/US, CIPP/G, ARM, RPLU+ PRIVACY PROFESSIONALS LLC gpalagonia@privacyprofessionals.com

More information

HIPAA. What s New & What Do I Have To Do? Presented by Leslie Canham, CDA, RDA, CSP (Certified Speaking Professional)

HIPAA. What s New & What Do I Have To Do? Presented by Leslie Canham, CDA, RDA, CSP (Certified Speaking Professional) HIPAA Infection Control OSHA Dental Practice Act HIPAA What s New & What Do I Have To Do? Presented by Leslie Canham, CDA, RDA, CSP (Certified Speaking Professional) In the dental field since 1972, Leslie

More information

ARRA 2009: Privacy and Security Provisions. Deven McGraw

ARRA 2009: Privacy and Security Provisions. Deven McGraw ARRA 2009: Privacy and Security Provisions Deven McGraw 1 Health Privacy Project at CDT Health IT and electronic health information exchange have tremendous potential to improve health care quality, reduce

More information

Health Law Diagnosis

Health Law Diagnosis February Page 1 of 2013 11 Health Law Diagnosis HHS Releases Final HITECH Omnibus Rule After waiting over two years from the publication of the Notice of Proposed Rulemaking to implement provisions of

More information

GETTING SERIOUS ABOUT MEDICAID COMPLIANCE:SECTION 6402 OF PPACA AND THE DUTY OF DISCLOSURE OF IDENTIFIED OVERPAYMENTS 7/14/10

GETTING SERIOUS ABOUT MEDICAID COMPLIANCE:SECTION 6402 OF PPACA AND THE DUTY OF DISCLOSURE OF IDENTIFIED OVERPAYMENTS 7/14/10 GETTING SERIOUS ABOUT MEDICAID COMPLIANCE:SECTION 6402 OF PPACA AND THE DUTY OF DISCLOSURE OF IDENTIFIED OVERPAYMENTS 7/14/10 JAMES G. SHEEHAN NEW YORK MEDICAID INSPECTOR GENERAL James.Sheehan@OMIG.NY.GOV

More information

AMA Practice Management Center, What you need to know about the new health privacy and security requirements

AMA Practice Management Center, What you need to know about the new health privacy and security requirements 1. HIPAA Security Rule Johns, Merida L., Information Security, in Johns, Merida L. (ed.) Health Information Management Technology, an Applied Approach, AHIMA: Chicago, IL, 2nd ed. 2007, chapter 19, pp.

More information

HIPAA Compliance. PART I: HHS Final Omnibus HIPAA Rules

HIPAA Compliance. PART I: HHS Final Omnibus HIPAA Rules HIPAA Compliance PART I: HHS Final Omnibus HIPAA Rules Colin J. Zick Foley Hoag LLP (617) 832-1000 www.foleyhoag.com February 6, 2013 www.securityprivacyandthelaw.com HIPAA Compliance: PART I 1 Finally!

More information

To: Our Clients and Friends January 25, 2013

To: Our Clients and Friends January 25, 2013 Life Sciences and Health Care Client Service Group To: Our Clients and Friends January 25, 2013 Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the Health

More information

SATINSKY CONSULTING, LLC FINAL OMNIBUS HIPAA PRIVACY AND SECURITY RULE

SATINSKY CONSULTING, LLC FINAL OMNIBUS HIPAA PRIVACY AND SECURITY RULE SATINSKY CONSULTING, LLC FINAL OMNIBUS HIPAA PRIVACY AND SECURITY RULE This newsletter summarizes the highlights of the Final Omnibus HIPAA Privacy and Security Rule announced by the Department of Health

More information

Compliance Concerns: Reporting, Investigating, and Protection from Retaliation

Compliance Concerns: Reporting, Investigating, and Protection from Retaliation Issuing Department: Internal Audit, Compliance, and Enterprise Risk Management Effective Date: 12/1/2014 Reissue Date: 9/26/2016 Compliance Concerns: Reporting, Investigating, and Protection from Retaliation

More information

HIPAA, 42 CFR PART 2, AND MEDICAID COMPLIANCE STANDARDS POLICIES AND PROCEDURES

HIPAA, 42 CFR PART 2, AND MEDICAID COMPLIANCE STANDARDS POLICIES AND PROCEDURES SALISH BHO HIPAA, 42 CFR PART 2, AND MEDICAID COMPLIANCE STANDARDS POLICIES AND PROCEDURES Policy Name: BREACH NOTIFICATION REQUIREMENTS Policy Number: 5.16 Reference: 45 CFR Parts 164 Effective Date:

More information

MEMORANDUM. Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know

MEMORANDUM. Health Care Information Privacy The HIPAA Regulations What Has Changed and What You Need to Know 1801 California Street Suite 4900 Denver, CO 80202 303-830-1776 Facsimile 303-894-9239 MEMORANDUM To: Adam Finkel, Assistant Director, Government Relations, NCRA From: Mel Gates Date: December 23, 2013

More information

[Name of Organization] HIPAA Incident/Breach Investigation Procedure 4

[Name of Organization] HIPAA Incident/Breach Investigation Procedure 4 Addendum II [Name of Organization] HIPAA Incident/Breach Investigation Procedure 4 I. Purpose To distinguish between (1) cases in which our HIPAA policy was not correctly followed but such violation did

More information

HIPAA Omnibus Rule. Critical Changes for Providers Presented by Susan A. Miller, JD. Hosted by

HIPAA Omnibus Rule. Critical Changes for Providers Presented by Susan A. Miller, JD. Hosted by HIPAA Omnibus Rule Critical Changes for Providers Presented by Susan A. Miller, JD Hosted by agenda What the Omnibus Rule includes + Effective and Compliance Dates Security Breach Notification Enforcement

More information

Stark Self-Disclosure. Thomas S. Crane 1/ Mintz Levin Cohn Ferris Glovsky and Popeo, PC

Stark Self-Disclosure. Thomas S. Crane 1/ Mintz Levin Cohn Ferris Glovsky and Popeo, PC Stark Self-Disclosure Thomas S. Crane 1/ Mintz Levin Cohn Ferris Glovsky and Popeo, PC A. Background 1. Stark Law The Physician Self-Referral Statute (or the Stark Law ) prohibits a physician from referring

More information

HIPAA Compliance Under the Magnifying Glass

HIPAA Compliance Under the Magnifying Glass HIPAA Compliance Under the Magnifying Glass July 30, 2013 Stacy Harper, JD, MHSA, CPC A Webinar Provided by Presenter Stacy Harper Lathrop & Gage, LLP sharper@lathropgage.com 913-451-5125 The information

More information

OCR Phase II Audit Protocol Breach Notification. HIPAA COW Spring Conference 2017 Page 1 Boerner Consulting, LLC

OCR Phase II Audit Protocol Breach Notification. HIPAA COW Spring Conference 2017 Page 1 Boerner Consulting, LLC Audit Type Section Key Activity Established Performance Criteria Audit Inquiry 12 Samples Requested Breach 164.414(a) Administrative 164.414(a) 164.414(a) 5 Inquiry of Mgmt Requirements Administrative

More information

True or False? HIPAA Update: Avoiding Penalties. Preliminaries. Kim C. Stanger IHCA (7/15)

True or False? HIPAA Update: Avoiding Penalties. Preliminaries. Kim C. Stanger IHCA (7/15) Protected Health Info HIPAA Update: Avoiding Penalties IHCA (7/15) Preliminaries This presentation is similar to any other legal education materials designed to provide general information on pertinent

More information

HTKT.book Page 1 Monday, July 13, :59 PM HIPAA Tool Kit 2017

HTKT.book Page 1 Monday, July 13, :59 PM HIPAA Tool Kit 2017 HIPAA Tool Kit 2017 Contents Introduction...1 About This Manual... 1 A Word About Covered Entities... 1 A Brief Refresher Course on HIPAA... 2 A Brief Update on HIPAA... 2 Progress Report... 4 Ongoing

More information

HIPAA Breach Notification Case Studies on What to Do and When to Report

HIPAA Breach Notification Case Studies on What to Do and When to Report HIPAA Breach Notification Case Studies on What to Do and When to Report AHLA Physicians and Physician Organizations and Hospitals and Health Systems Law Institute February 9 and10, 2012 Colleen M. McClorey,

More information

HIPAA: Impact on Corporate Compliance

HIPAA: Impact on Corporate Compliance HIPAA: Impact on Corporate Compliance AAPC HEALTHCON April 2014 Stacy Harper, JD, MHSA, CPC Disclaimer The information provided is for educational purposes only and is not intended to be considered legal

More information

503 SURVIVING A HIPAA BREACH INVESTIGATION

503 SURVIVING A HIPAA BREACH INVESTIGATION 503 SURVIVING A HIPAA BREACH INVESTIGATION Presented by Nicole Hughes Waid, Esq. Mark J. Swearingen, Esq. Celeste H. Davis, Esq. Regional Manager 1 Surviving a HIPAA Breach Investigation: Enforcement Presented

More information

Continuous Compliance: An Operational Approach Must Address HIPAA

Continuous Compliance: An Operational Approach Must Address HIPAA Continuous Compliance: An Operational Approach Must Address HIPAA Alfonso P. Conti, MPA Manager, Grassi & Co. Claudia Hinrichsen, Esq. Partner, Health Law Partners February 27, 2013 Compliance in Total

More information

ACC Compliance and Ethics Committee Presentation February 19, 2013

ACC Compliance and Ethics Committee Presentation February 19, 2013 ACC Compliance and Ethics Committee Presentation February 19, 2013 Melinda G. Murray Associate General Counsel, Holy Cross Hospital and Jill M. Girardeau Partner, Womble Carlyle Sandridge & Rice, LLP HIPAA

More information

Health Care Reform under the Patient Protection and Affordable Care Act ( PPACA ) provisions effective January 1, 2014

Health Care Reform under the Patient Protection and Affordable Care Act ( PPACA ) provisions effective January 1, 2014 The New Health Care Landscape Today s Agenda Health Care Reform under the Patient Protection and Affordable Care Act ( PPACA ) provisions effective January 1, 2014 Exchanges and Qualified Health Plans

More information

HIPAA Privacy Overview

HIPAA Privacy Overview HIPAA Privacy Overview Benefit Advisors Network Stacy H. Barrow sbarrow@marbarlaw.com February 8, 2017 2017 Marathas Barrow Weatherhead Lent LLP. All Rights Reserved. 1 Overview of Presentation HIPAA Overview

More information

HIPAA AND ONLINE BACKUP WHAT YOU NEED TO KNOW ABOUT

HIPAA AND ONLINE BACKUP WHAT YOU NEED TO KNOW ABOUT WHAT YOU NEED TO KNOW ABOUT HIPAA AND ONLINE BACKUP Learn more about how KeepItSafe can help to reduce costs, save time, and provide compliance for online backup, disaster recovery-as-a-service, mobile

More information

Changes to HIPAA Under the Omnibus Final Rule

Changes to HIPAA Under the Omnibus Final Rule Changes to HIPAA Under the Omnibus Final Rule Kimberly J. Kannensohn and Nathan A. Kottkamp, McGuireWoods 1 The Long-Awaited HIPAA Final Rule On Jan. 17, 2013, the Department of Health and Human Services

More information

Corporate Compliance Program. Intended Audience: All SEH Associates 2016 Content Expert: Lisa Frey -

Corporate Compliance Program. Intended Audience: All SEH Associates 2016 Content Expert: Lisa Frey - Corporate Compliance Program Intended Audience: All SEH Associates 2016 Content Expert: Lisa Frey - lisa.frey@stelizabeth.com Developed 2012, reviewed Dec 2015 What is Corporate Compliance? Hospitals,

More information

The Guild for Exceptional Children HIPAA Breach Notification Policy and Procedure

The Guild for Exceptional Children HIPAA Breach Notification Policy and Procedure The Guild for Exceptional Children HIPAA Breach Notification Policy and Procedure Purpose To provide for notification in the case of breaches of Unsecured Protected Health Information ( Unsecured PHI )

More information

Interpreters Associates Inc. Division of Intérpretes Brasil

Interpreters Associates Inc. Division of Intérpretes Brasil Interpreters Associates Inc. Division of Intérpretes Brasil Adherence to HIPAA Agreement Exhibit B INDEPENDENT CONTRACTOR PRIVACY AND SECURITY PROTECTIONS RECITALS The purpose of this Agreement is to enable

More information

HITECH/HIPAA Omnibus Final Rule: Implications for Hospices. Elizabeth S. Warren May 3, 2013

HITECH/HIPAA Omnibus Final Rule: Implications for Hospices. Elizabeth S. Warren May 3, 2013 HITECH/HIPAA Omnibus Final Rule: Implications for Hospices Elizabeth S. Warren May 3, 2013 Final Rule is Finally Here Published January 25, 2013 (78 Fed. Reg. 5566) Effective March 26, 2013 Compliance

More information

NOTIFICATION OF PRIVACY AND SECURITY BREACHES

NOTIFICATION OF PRIVACY AND SECURITY BREACHES NOTIFICATION OF PRIVACY AND SECURITY BREACHES Overview The UT Health Science Center at San Antonio (Health Science Center) is required to report all breaches of protected health information and personally

More information

Repay Overpayments (18 USC 1347; 42 CFR et seq.)

Repay Overpayments (18 USC 1347; 42 CFR et seq.) Repay Overpayments (18 USC 1347; 42 CFR 401.301 et seq.) Repaying Overpayments If provider has received an overpayment, provider must: Return the overpayment to federal agency, state, intermediary, or

More information

HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT

HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT HIPAA HEALTH INSURANCE PORTABILITY & ACCOUNTABILITY ACT HIPAA OMNIBUS FINAL RULE HITECH GINA TERMINOLOGY OMNIBUS FINAL RULE Issued January 23, 2013 Effective March 26, 2013 Modified HIPAA privacy and security

More information

"HIPAA FOR LAW FIRMS" WHAT EVERY LAW FIRM NEEDS TO KNOW ABOUT HIPAA

HIPAA FOR LAW FIRMS WHAT EVERY LAW FIRM NEEDS TO KNOW ABOUT HIPAA "HIPAA FOR LAW FIRMS" WHAT EVERY LAW FIRM NEEDS TO KNOW ABOUT HIPAA Jeanne M. Born, RN, JD SOUTH CAROLINA ASSOCIATION OF LEGAL ADMINISTRATORS THURSDAY, APRIL 14, 2016 Jborn@nexsenpruet.com What Every Law

More information

GOALS OF THIS PRESENTATION HOW WE GOT HERE WHERE WE ARE MANDATORY COMPLIANCE REQUIREMENTS LESSONS FROM MANDATORY COMPLIANCE IN NEW YORK MY PREDICTIONS

GOALS OF THIS PRESENTATION HOW WE GOT HERE WHERE WE ARE MANDATORY COMPLIANCE REQUIREMENTS LESSONS FROM MANDATORY COMPLIANCE IN NEW YORK MY PREDICTIONS MANDATORY COMPLIANCE: WHAT THE FUTURE LOOKS LIKE HCCA SOUTH ATLANTIC REGIONAL MEETING 1/28/11 JAMES G. SHEEHAN NEW YORK MEDICAID INSPECTOR GENERAL James.Sheehan@Omig.NY.gov GOALS OF THIS PRESENTATION HOW

More information

Compliance Program. Health First Health Plans Medicare Parts C & D Training

Compliance Program. Health First Health Plans Medicare Parts C & D Training Compliance Program Health First Health Plans Medicare Parts C & D Training Compliance Training Objectives Meeting regulatory requirements Defining an effective compliance program Communicating the obligation

More information

HIPAA PRIVACY AND SECURITY AWARENESS

HIPAA PRIVACY AND SECURITY AWARENESS HIPAA PRIVACY AND SECURITY AWARENESS Introduction The Health Insurance Portability and Accountability Act (known as HIPAA) was enacted by Congress in 1996. HIPAA serves three main purposes: To protect

More information

The Impact of the Stimulus Act on HIPAA Privacy and Security

The Impact of the Stimulus Act on HIPAA Privacy and Security The Impact of the Stimulus Act on Webinar March 12, 2009 Practical Tools for Seminar Learning Copyright 2009 American Health Information Management Association. All rights reserved. Disclaimer The American

More information

HIPAA & HITECH Privacy & Security. Volunteer Annual Review 2017

HIPAA & HITECH Privacy & Security. Volunteer Annual Review 2017 HIPAA & HITECH Privacy & Security Volunteer Annual Review 2017 HIPAA In 1996, state and federal governments enacted protection for patient health information by signing into law the Health Insurance Portability

More information

Transparency, Reporting & Data Mining

Transparency, Reporting & Data Mining Transparency, Reporting & Data Mining Kimberly Brandt, CHC, JD Alston & Bird, LLP Shawn DeGroot, CHC-F, CCEP, CHRC Vice President of Corporate Responsibility Regional Health Size and Scope of Data 2 1

More information

GUIDE TO PATIENT PRIVACY AND SECURITY RULES

GUIDE TO PATIENT PRIVACY AND SECURITY RULES AMERICAN ASSOCIATION OF ORTHODONTISTS GUIDE TO PATIENT PRIVACY AND SECURITY RULES I. INTRODUCTION The American Association of Orthodontists ( AAO ) has prepared this Guide and the attachment to assist

More information